CVE-2024-0516
Royal-elementor-addons
CVE-2024-0516: A critical WordPress plugin vulnerability exists in the Royal Elementor Addons and Templates plugin. This flaw allows unauthenticated attackers to modify post metadata due to a missing capability check in the 'wpr_update_form_action_meta' function, affecting versions up to 1.3.87. With a low SOCRadar Vulnerability Risk Score (SVRS) of 30, while not immediately critical, this metadata manipulation could lead to potential website defacement or data compromise if exploited in conjunction with other vulnerabilities. The vulnerability, categorized under CWE-862 (Missing Authorization), could enable attackers to inject malicious content or redirect users. Although the CVSS score is 0, indicating minimal immediate impact as a standalone issue, the possibility for exploitation in the wild necessitates a prompt update to the latest plugin version to mitigate potential risks. Website administrators should prioritize patching their WordPress installations to prevent unauthorized modifications and maintain site integrity. Regular security audits are crucial for detecting and addressing vulnerabilities before they can be exploited.
Indicators of Compromise
Exploits
News
Social Media
Affected Software
References
CWE Details
CVE Radar
Real-time CVE Intelligence & Vulnerability Management Platform
CVE Radar provides comprehensive vulnerability intelligence by monitoring CVE databases, security advisories, and threat feeds. Get instant updates on new vulnerabilities, exploit details, and mitigation strategies specific to your assets.